Our takeCISA advisory: Rockwell CompactLogix 5380, ControlLogix 5580 (V36-V37) and 1756-EN4TR modules have a DoS vulnerability (CVE-2026-9636). If you run these on your OT network, patch during the next maintenance window.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:Update ControlLogix 5580, CompactLogix 5380, and GuardLogix 5580 controllers running firmware V36–V37, plus any 1756-EN4TR modules. The DoS vulnerability is confirmed by CISA; patch during the next maintenance window if these devices are reachable on your plant or control network.
What this means for you — Lean IT orgs:If you run Rockwell CompactLogix 5380 or ControlLogix 5580 controllers on firmware version 36 or 37, update them as soon as you can. This flaw lets an attacker knock the device offline; most small teams should check with their equipment vendor or integrator for the update steps.
What this means for you — MSP:Check client environments for Rockwell ControlLogix 5580, CompactLogix 5380, or GuardLogix 5580 running firmware V36–V37 and 1756-EN4TR modules. Apply the Rockwell patch; these are common in light manufacturing and utilities OT networks.
What this means for you — Researcher:Review the CISA advisory and linked CSAF for CVE-2026-9636 details on Rockwell CompactLogix 5380, ControlLogix 5580, and 1756-EN4TR modules. Test in isolated OT labs if you track ICS denial-of-service vectors.